木马程序的查杀设计与实现
摘 要
随着即时通讯市场的爆炸式增长,在线即时通讯软件——QQ的使用者越来越多,当然,随之带来的网络安全隐患也不断增加。利用QQ这类即时通讯工具来进行传播的病毒,已经逐渐成为新病毒的流行趋势。QQ本身安全性能的缺陷已经不断衍生出各种类型的QQ木马病毒。
本文所阐述的基于面向对象编程技术(Delphi 7)的木马查杀系统是一个专门针对基于钩子技术、动态链接库(DLL)设计的一类特殊木马的查杀系统。
木马设计过程中采用了钩子技术,这与近阶段QQ木马传播、隐藏技术接轨,因此,基于该技术所设计的QQ木马查杀系统适用于当前正流行的QQ木马的查杀。
关键词:钩子技术、QQ、木马
The design and accomplishment of checking and killing Trojan horse procedure
ABSTRACT
As the explosive increase of the instant communication market, more and more people come to use the online instant communication software--QQ. Certainly, with it, potential security hazard of the network is ceaselessly increasing. The virus spreading with QQ--the instant communication tool has gradually become the fashion trend of new virus. The defect of QQ security performance has incessantly been deriving out kinds of QQ Trojan horse virus.
What this paper explains is the system of checking and killing Trojan horse, which is based on Object Oriented programming technology (Delphi 7). The system is wholly dead against a special kind of Trojan horse designing by hook technology and dynamic link library (DLL).
We have adopted hook technology in the Trojan horse design process, which joint with the nearly stage’s QQ Trojan horse hides and dissemination technology, So, the check and kill QQ Trojan horse system based on that technology is suitable to check and kill prevailing QQ Trojan horse at present.
KEYWORDS:hook technology, QQ,Trojan horse